PT-2026-107100 · Pypi · Hydra

CVE-2026-106439

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hydra versions 1.3.4 through 1.3.6 Hydra versions 1.4.0.dev1 through 1.4.0.dev9
Description Hydra stores legacy instantiate target blocklists and related execution-policy collections in mutable module-level state. An attacker controlling multiple sibling target entries can resolve hydra. internal.target policy.UNCONTROLLED EXECUTION TARGETS.discard through the instantiate() function to remove a denied target. Because sibling nodes are processed in insertion order against the same modified policy, the attacker can then invoke that target. This mutation persists in process-global state and can enable code execution with the application's privileges. A narrow execution whitelist supplied by trusted Python code is not bypassed by this direct mutation path.
Recommendations Update Hydra to version 1.3.7. Update Hydra to version 1.4.0.dev10.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106439
GHSA-MWJ6-RFH8-7QF4

Affected Products

Hydra